Privacy Policy
Last updated: August 2026
We do not log the content of your traffic, the sites you visit, the DNS queries you make, or the IP addresses you connect out to. Our servers are not configured to record that information, so it cannot be handed over, subpoenaed, or leaked.
1. What we collect
Only what is needed to run an account and keep a subscription honest:
- Email address — only if you sign up on the web. Used to send your sign-in link and account notices. Accounts created through the Telegram bot have no email at all.
- Telegram ID — if you use the bot or link your account to it, so we can deliver keys and answer support messages.
- Payment records — plan, amount, currency, date, and the payment processor's reference. Card numbers never reach our servers; Stripe handles them. Crypto payments are recorded as on-chain settlements against an invoice.
- Access credentials — the keys and subscription URLs issued to you, and which servers they exist on.
- Total bytes transferred per key — a running counter, nothing more. It exists to enforce the data cap on your plan and to spot resale abuse. It records volume, never destinations.
- Support messages — what you send us, so we can reply.
- Referral code — if you use the referral program, the link between referrer and referred account.
2. What we deliberately do not collect
- Browsing history, destination IPs, DNS queries, or any traffic content.
- Deep-packet inspection or traffic fingerprinting of our own users.
- Identity documents. We never ask for one. If you pay by card, Stripe may collect a billing address to process the payment — that stays with Stripe; we do not store names or addresses on our own servers.
- Third-party trackers, advertising pixels, or social widgets. There are none on this site.
Crypto payment (Lightning, USDT, USDC) lets you hold an account with no email and no card, which is the most private way to use the service.
3. Server logs
Like most websites, our storefront runs behind a web server that keeps short-term operational logs, which can include the IP address a request came from. We use them to debug outages and block abuse. Your connection IP is also held briefly in memory to rate-limit sign-in and contact requests, and is never written to our database.
These logs describe traffic to our storefront, not traffic through the proxy.
4. Analytics
We run a self-hosted Umami instance on our own server for aggregate page-view counts. It sets no analytics cookies and sends nothing to a third party — the data never leaves our machine. There is no Google Analytics, no Meta pixel, and no ad network on this site.
The only cookies we set are the ones that keep you signed in and remember a referral link. Nothing here tracks you across other websites.
5. Who else processes your data
We keep this list as short as we can:
- Stripe — card payments, if you pay by card.
- Resend — delivers sign-in and account emails.
- Telegram — if you use the bot, your messages pass through Telegram.
- Our hosting providers — they operate the physical machines our servers run on.
We do not sell, rent, or trade your data, and we do not share it for advertising.
6. How long we keep it
Account data — email, Telegram link, keys, usage counters, support messages — lives as long as your account does, and is erased when you delete it (see below).
Payment and invoice records are kept after deletion for accounting, chargeback disputes, and fraud prevention. Your email, Telegram ID, and access credentials are stripped from them first, leaving the transaction itself.
To be precise rather than flattering: these retained records still carry the payment processor's own reference (for example a Stripe customer or subscription ID, or an invoice ID). We can no longer tie those to a name or address, but the processor that issued them can. Paying with Lightning, USDT, or USDC avoids this entirely — there is no processor account behind a crypto invoice.
7. Deleting your account
You can delete your account yourself, at any time, from your dashboard. No email to support, no waiting.
If you signed up through the Telegram bot and never linked an email, you have no dashboard to sign in to — message us with /support in the bot and we will delete your account for you.
Deleting removes, immediately and permanently:
- Your access keys, deleted from every server they exist on.
- Any dedicated server you hold, destroyed along with its credentials.
- Your email address and sign-in tokens.
- Your Telegram link and support message history.
- Your bandwidth usage history and subscription URLs.
Deletion is immediate and cannot be undone. Your connection stops working the moment you confirm, any remaining paid time is forfeited, and no refund is issued. What remains afterwards is the de-identified payment record described in section 6.
8. Security
Sign-in links are single-use and expire quickly. Session tokens are stored hashed, never in plain text. Traffic to this site is served over HTTPS.
Nothing is perfectly secure. If your threat model is severe, pay with Lightning or USDT and use the Telegram bot — that way we hold no email address for you in the first place, and the safest data is the data we never collected.
9. Changes
If we change this policy we will update the date at the top. Material changes will be announced through the support channel.
10. Contact
Questions about your data, or want a copy of what we hold? Contact us. See also our Terms of Service.